Saturday, June 29, 2019

Security Alert. Your accounts was hacked by criminal group.

NOTE:  I smell desperation to "havrested" information here. Definitely a template someone most likely paid money for.  Stupidiots.  Done by dial up no less!  Probably from a cave somewhere. Are there caves in Uruguay?


From: <johanne.cormier@gynecolasalle.com> To: "ci121954" < > 21:28:31 CDT, Friday 28 June 2019

Hi, dear user of   We have installed one RAT software into you device For this moment your email account is hacked too. I know your password for this account [ ]: ci121954 Changed your password? You're doing great! But my software recognizes every such action. I'm updating passwords! I'm always one step ahead.... So... I have downloaded all confidential information from your system and I got some more evidence. The most interesting moment that I have discovered are videos records where you masturbating. I posted EternalBlue Exploit modification on porn site, and then you installed my malicious code (trojan) on your operation system. When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device. After installation, your front camera shoots video every time you masturbate, in addition, the software is synchronized with the video you choose. For the moment, the software has harvrested all your contact information from social networks and email addresses. If you need to erase all of your collected data, send me $600 in BTC (crypto currency). This is my Bitcoin wallet: 11NT1KhH3aXsRw4LS6PFFrT5fRkdZFmne You have 48 hours after reading this letter. After your transaction I will erase all your data. Otherwise, I will send video with your pranks to all your colleagues and friends!!! P.S. I'm asking you - not to answer this letter because the sender's address is fake, just to keep me incognito. And henceforth be more careful! Please visit only secure sites! Bye,Bye...



Envelope Sender: <johanne.cormier@gynecolasalle.com>
'From' Header: <johanne.cormier@gynecolasalle.com>
Subject: Security Alert. Your accounts was hacked by criminal group.
Timestamp: 21:28:31 CDT, Friday 28 June 2019
Message-ID: <004201d52e09$06f65d7a$8766a69c$@gynecolasalle.com>

Client IP Address: 179.25.189.132
Client GeoIP Lookup: Uruguay
Email Size: 2.6 kB
Encrypted? No


Message ID: <004201d52e09$06f65d7a$8766a69c$@gynecolasalle.com>
Return Path: <johanne.cormier@gynecolasalle.com>
Reply To:
MIME Version: 1.0
Content Type: text/plain; charset="ibm852"
Received:
from mx1-us1.ppe-hosted.com (unknown [10.110.49.6]) by pure.maildistiller.com with ESMTPS id E8BF71E0053 for < >; Sat, 29 Jun 2019 02:28:30 +0000 (UTC)

from r179-25-189-132.dialup.adsl.anteldata.net.uy (r179-25-189-132.dialup.adsl.anteldata.net.uy [179.25.189.132]) by mx1-us1.ppe-hosted.com with ESMTP id 75E05B00055 for < >; Sat, 29 Jun 2019 02:28:30 +0000 (UTC)

Be sure to read this message! Your personal data is threatened!

NOTE:  Saudi Arabia is still trying to "harvrested" your info .... or not ... this is just laughable at every sentence.

From: <canagao@pacbell.net> To: "mci121954" <  >  11:08:46 CDT, Saturday 29 June 2019


Hi, dear user of domain.com We have installed one RAT software into you device For this moment your email account is hacked too. I know your password for this account [email@domain.com]: mci121954 Changed your password? You're doing great! But my software recognizes every such action. I'm updating passwords! I'm always one step ahead.... So... I have downloaded all confidential information from your system and I got some more evidence. The most interesting moment that I have discovered are videos records where you masturbating. I posted EternalBlue Exploit modification on porn site, and then you installed my malicious code (trojan) on your operation system. When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device. After installation, your front camera shoots video every time you masturbate, in addition, the software is synchronized with the video you choose. For the moment, the software has harvrested all your contact information from social networks and email addresses. If you need to erase all of your collected data, send me $600 in BTC (crypto currency). This is my Bitcoin wallet: 11NT1KhH3aXsRw4LS6PFFrT5fRkdZFmne You have 48 hours after reading this letter. After your transaction I will erase all your data. Otherwise, I will send video with your pranks to all your colleagues and friends!!! P.S. I'm asking you - not to answer this letter because the sender's address is fake, just to keep me incognito. And henceforth be more careful! Please visit only secure sites! Bye,Bye...



Message ID: <002b01d52eae$0584ab8d$571089b1$@pacbell.net>
Return Path: <canagao@pacbell.net>
Reply To:
MIME Version: 1.0
Content Type: text/plain; charset="ibm852"
Received:
from mx1-us4.ppe-hosted.com (unknown [10.110.49.109]) by pure.maildistiller.com with ESMTPS id 55C334006A for <email@domain.com>; Sat, 29 Jun 2019 16:08:46 +0000 (UTC)

from [51.235.156.159] (unknown [51.235.156.159]) by mx1-us4.ppe-hosted.com with ESMTP id 816C6B40064 for <email@domain.com>; Sat, 29 Jun 2019 16:08:45 +0000 (UTC)



Envelope Sender: <canagao@pacbell.net>
'From' Header: <canagao@pacbell.net>
Subject: Be sure to read this message! Your personal data is threatened!
Timestamp: 11:08:46 CDT, Saturday 29 June 2019
Message-ID: <002b01d52eae$0584ab8d$571089b1$@pacbell.net>

Client IP Address: 51.235.156.159
Client GeoIP Lookup: Saudi Arabia
Email Size: 2.5 kB
Encrypted? No

Thursday, June 27, 2019

From: Miss Ann Brahima

From: ann Brahima <annbrahima@yahoo.com> To: dsayers24@gmail.com 15:19:00 CDT, Thursday 27 June 2019


From: Miss Ann Brahima Strickly confidential attention !!!!  A cry for help It is a pleasure to introduce you to business that will mark the beginning of never ending family relationship, I hope that this proposal will not be an inconvenience or embarrassment to you..I must not hesitate to confide in you this simple and sincere business. I am Miss Ann Brahima the only child of late Brahima Toure who was a famous cocoa merchant.I am 25 years old from Cote D'Ivoire. My late father operated his cocoa business in abidjan Cote D'Ivoire under partnership but unfortunately his business associates poisoned him in order to claim his wealth in a cocktail party held in his honor as the director of the company.When he was poisoned he was rushed to the hospital. It was in the hospital that I secretly dislcosed to the cause of the sickness and also that I deposited the sum of £ 4.5million pounds with an international bank here in abidjan Cote D'Ivoire and that it was made the next of kin to inherit this in his record \ file. I have therefore advised me to look for a trustworthy, trustworthy and God fearing oversea partner who will assist me to transfer this funds to their own account abroad strictly for investment purposes and to finish my education this is because he did not want his associates to raise an eyebrow on his funds.He also advised me to avoid his associates who will be running after my dear life I finally died in the hospital after two days of admission. I am requesting for your assistance to transfer this funds for an investment purposes. I hope to travel with you to your country after a successful transfer of these funds. The contact of the bank will be given to you as soon as you show your interest and willingness to me.You can now instruct them on where and how this funds will be transferred. I am offering you 15% of the total sum of £ 4.5 million as commission for your assistance to transfer this fund. May i strongly re-emphasize that this transaction is highly confidential, and this will be successful within 10 days. Thanks and yours faithful Miss Ann Brahima !!!!


Message ID: <334450366.663912.1561666733893@mail.yahoo.com>
Return Path: <annbrahima@yahoo.com>
Reply To: annbrahima101@gmail.com
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Received:
from mx1-us4.ppe-hosted.com (unknown [10.7.66.41]) by pure.maildistiller.com with ESMTPS id 3A3B71A0067 for < >; Thu, 27 Jun 2019 20:19:00 +0000 (UTC)

from sonic311-14.consmr.mail.bf2.yahoo.com (sonic311-14.consmr.mail.bf2.yahoo.com [74.6.131.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us4.ppe-hosted.com with ESMTPS id 0A22D4C0073 for < >; Thu, 27 Jun 2019 20:18:59 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic311.consmr.mail.bf2.yahoo.com with HTTP; Thu, 27 Jun 2019 20:18:58 +0000



Envelope Sender: <annbrahima@yahoo.com>
'From' Header: ann Brahima <annbrahima@yahoo.com>
Subject: From: Miss Ann Brahima
Timestamp: 15:19:00 CDT, Thursday 27 June 2019
Message-ID: <334450366.663912.1561666733893@mail.yahoo.com>


Client IP Address: 74.6.131.124
Client GeoIP Lookup: United States
Email Size: 5.1 kB
Encrypted? No

I NEED YOUR VERY URGENT ASSISTANCE PLEASE

From: NEIL WAUDBY <telexroomconfirmation@gmail.com> To: undisclosed-recipients:;  06:25:11 CDT, Thursday 27 June 2019


My dear I am contacting you based on a financial opportunity I discovered here in our bank. It’s about an abandoned sum of 35 million USD from our Audit report, that belongs to one of our foreign customers, a citizen of your country that shares the same surname with you, who died along with his entire family on 11th March 2004 in train bombing in Madrid. The banking policy can only allow the release of such funds to a benefactor through an application as next of kin to the deceased. Since no one has come up since ten years. I am almost 110% sure that no one is aware of the existence of these funds.In conclusion, it’s my concern to demand your ultimate honesty, co-operation and confidentiality.I GUARANTEE that this process would be executed under a legitimate arrangement that would legally protect you from any breach of law.Your interest shall be protected in this transaction therefore you should not have any fears as all necessary arrangement have been done for a smooth fund transfer.I got your name from the internet. Neil Waudby


Message ID: <CAJxar4PRi8E2+SkFjMUqv4t10sc71i_qEbV9Hn+HgZXBvaV4QA@mail.gmail.com>
Return Path: <telexroomconfirmation@gmail.com>
Reply To: neilwaudby@mail.ru
MIME Version: 1.0
Content Type: text/plain; charset="UTF-8"
Received:
from mx1-us1.ppe-hosted.com (unknown [10.110.48.236]) by pure.maildistiller.com with ESMTPS id 77F2940052 for < >; Thu, 27 Jun 2019 11:25:11 +0000 (UTC)

from mail-qk1-f193.google.com (mail-qk1-f193.google.com [209.85.222.193]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us1.ppe-hosted.com with ESMTPS id 66C9340007C for < >; Thu, 27 Jun 2019 11:25:11 +0000 (UTC)

by mail-qk1-f193.google.com with SMTP id l128so1362865qke.2 for < >; Thu, 27 Jun 2019 04:25:11 -0700 (PDT)

by 2002:ac8:2c14:0:0:0:0:0 with HTTP; Thu, 27 Jun 2019 04:25:10 -0700 (PDT)



Envelope Sender: <telexroomconfirmation@gmail.com>
'From' Header: NEIL WAUDBY <telexroomconfirmation@gmail.com>
Subject: I NEED YOUR VERY URGENT ASSISTANCE PLEASE
Timestamp: 06:25:11 CDT, Thursday 27 June 2019
Message-ID: <CAJxar4PRi8E2+SkFjMUqv4t10sc71i_qEbV9Hn+HgZXBvaV4QA@mail.gmail.com>


Client IP Address: 209.85.222.193
Client GeoIP Lookup: United States
Email Size: 4.0 kB
Encrypted? No

Wednesday, June 26, 2019

Hackers know password from your account. Password must be changed now.

From: <mail@mrhird.co.uk> To: "hotday" <insert@email.com>  02:45:03 CDT, Wednesday 26 June 2019


Hi, dear user of somedomain.com We have installed one RAT(trojan) software into you device. For this moment your email account is hacked. I know your password for this account [<insert@email.com>]: hotday Changed your password? You're doing great! But my software recognizes every such action. I'm updating passwords! I'm always one step ahead.... So... I have downloaded all confidential information from your system and I got some more evidence. The most interesting moment that I have discovered are videos records where you masturbating. I posted my virus on porn site, and then you installed it on your operation system. When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device. After installation, your front camera shoots video every time you masturbate, in addition, the software is synchronized with the video you choose. For the moment, the software has harvrested all your contact information from social networks and email addresses. If you need to erase all of your collected data, send me $600 in BTC (crypto currency). This is my Bitcoin wallet: 15hcdsqcsH2QoevpuHRM45xKBRC9UBrVha You have 48 hours after reading this letter. After your transaction I will erase all your data. Otherwise, I will send video with your pranks to all your colleagues and friends!!! P.S. I'm asking you not to answer this letter because the sender's address is fake, just to keep me incognito. And henceforth be more careful! Please visit only secure sites! Bye!


Message ID: <001701d52c0c$037a5066$a1c6668c@noldfu>
Return Path: <mail@mrhird.co.uk>
Reply To:
MIME Version: 1.0
Content Type: text/plain; charset="ibm852"
Received:
from mx1-us1.ppe-hosted.com (unknown [10.110.48.236]) by pure.maildistiller.com with ESMTPS id 698858005B for <insert@email.com>; Wed, 26 Jun 2019 07:45:03 +0000 (UTC)

from [37.104.146.153] (unknown [37.104.146.153]) by mx1-us1.ppe-hosted.com with ESMTP id ECF2B400069 for <insert@email.com>; Wed, 26 Jun 2019 07:45:02 +0000 (UTC)

Envelope Sender: <mail@mrhird.co.uk>
'From' Header: <mail@mrhird.co.uk>
Subject: Hackers know password from your account. Password must be changed now.
Timestamp: 02:45:03 CDT, Wednesday 26 June 2019
Message-ID: <001701d52c0c$037a5066$a1c6668c@noldfu>


Client IP Address: 37.104.146.153
Client GeoIP Lookup: Saudi Arabia
Email Size: 2.5 kB
Encrypted? No

PROFITABLE BUSINESS RECOMMEND

From: admin@seinoindomobil.co.id To: Recipients <admin@seinoindomobil.co.id>  06:01:05 CDT, Wednesday 26 June 2019


Hello, I am Martin Peter, Operational Risk Control Manager and member of the UBS group executive board. I am looking for an international business partner to work with me in a financial transaction with good benefit. During the recent auditing of bank accounts and services of our bank, I discovered non-resident bank account which haven't been operated for a long time. This account belongs to a late business mogul who was involved in a Plane crash on 7th June 2012 resulting to his death and his family members. Until now, nobody knows about his bank account with UBS Investment Bank. This said account holds 22,300,000 GBP (Twenty two million, three hundred thousand GBP Sterling only) and I would like you to indicate your interest to stand as the "Foreign Beneficiary". Also, I will count on your sense of secrecy and confidentiality, in order to avoid risky exposure, considering the sensitivity and magnitude of this project. contact me if interested for more information via (care4martin@linuxmail.org). See below link on your knowledge about late Mr. Ron Bramlage... ...( http://www2.ljworld.com/news/2012/jun/08/bramlage-family-parish-grappling-loss/ ) Thanks and best regards, Contact email: care4martin@linuxmail.org Contact person: Mr. Martin, Operational Risk Control Manager, UBS Investment Bank, London.? P.S. I'm anxiously waiting forward to your urgent response.


Envelope Sender: <admin@seinoindomobil.co.id>
'From' Header: admin@seinoindomobil.co.id
Subject: PROFITABLE BUSINESS RECOMMEND
Timestamp: 06:01:05 CDT, Wednesday 26 June 2019
Message-ID: <20190626190027.EF18B6A6BC9@mail.seinoindomobil.co.id>


Client IP Address: 202.158.69.151
Client GeoIP Lookup: Indonesia
Email Size: 3.4 kB
Encrypted? No

Message ID: <20190626190027.EF18B6A6BC9@mail.seinoindomobil.co.id>
Return Path: <admin@seinoindomobil.co.id>
Reply To: care4martin@linuxmail.org
MIME Version: 1.0
Content Type: text/plain; charset="iso-8859-1"
Received:
from mx1-us5.ppe-hosted.com (unknown [10.110.50.7]) by pure.maildistiller.com with ESMTPS id BD46C40071 for < >; Wed, 26 Jun 2019 11:01:04 +0000 (UTC)

from mail.seinoindomobil.co.id (ip69-151.cbn.net.id [202.158.69.151]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1-us5.ppe-hosted.com with ESMTPS id 7895A4C0066 for < >; Wed, 26 Jun 2019 11:01:04 +0000 (UTC)

from localhost (localhost [127.0.0.1]) by mail.seinoindomobil.co.id (Postfix) with ESMTP id 4FF676BFBDE; Wed, 26 Jun 2019 15:00:45 -0400 (EDT)

from mail.seinoindomobil.co.id ([127.0.0.1]) by localhost (mail.seinoindomobil.co.id [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id 4pUiRH4qpeJl; Wed, 26 Jun 2019 15:00:44 -0400 (EDT)

from localhost (localhost [127.0.0.1]) by mail.seinoindomobil.co.id (Postfix) with ESMTP id 0FA7D6BFBD6; Wed, 26 Jun 2019 15:00:37 -0400 (EDT)

from mail.seinoindomobil.co.id ([127.0.0.1]) by localhost (mail.seinoindomobil.co.id [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id la1Kxtsgsy7E; Wed, 26 Jun 2019 15:00:36 -0400 (EDT)

from [172.20.10.8] (unknown [129.205.113.212]) by mail.seinoindomobil.co.id (Postfix) with ESMTPA id EF18B6A6BC9; Wed, 26 Jun 2019 15:00:27 -0400 (EDT)

The decision to suspend your account. Waiting for payment.

NOTE: How do you "harvrested" something????

From: <kmfun@sbcglobal.net> To: "hotday" <insertemail@.com>


Hi, dear user of (insert).com We have installed one RAT(trojan) software into you device. For this moment your email account is hacked. I know your password for this account [<insertemail@.com>]: hotday Changed your password? You're doing great! But my software recognizes every such action. I'm updating passwords! I'm always one step ahead.... So... I have downloaded all confidential information from your system and I got some more evidence. The most interesting moment that I have discovered are videos records where you masturbating. I posted my virus on porn site, and then you installed it on your operation system. When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device. After installation, your front camera shoots video every time you masturbate, in addition, the software is synchronized with the video you choose. For the moment, the software has harvrested all your contact information from social networks and email addresses. If you need to erase all of your collected data, send me $600 in BTC (crypto currency). This is my Bitcoin wallet: 15hcdsqcsH2QoevpuHRM45xKBRC9UBrVha You have 48 hours after reading this letter. After your transaction I will erase all your data. Otherwise, I will send video with your pranks to all your colleagues and friends!!! P.S. I'm asking you not to answer this letter because the sender's address is fake, just to keep me incognito. And henceforth be more careful! Please visit only secure sites! Bye!


Message ID: <D3E398DB6FA8A02C1C672490575FD3E3@12I28OK6SM>
Return Path: <kmfun@sbcglobal.net>
Reply To:
MIME Version: 1.0
Content Type: text/plain; charset="ibm852"
Received:
from mx1-us3.ppe-hosted.com (unknown [10.7.66.37]) by pure.maildistiller.com with ESMTPS id BB1FC1A0071 for <insertemail@.com>; Wed, 26 Jun 2019 16:30:09 +0000 (UTC)

from host-156.221.241.54-static.tedata.net (unknown [156.221.54.241]) by mx1-us3.ppe-hosted.com with ESMTP id 2AFC8B40056 for <insertemail@.com>; Wed, 26 Jun 2019 16:30:09 +0000 (UTC)


Envelope Sender: <kmfun@sbcglobal.net>
'From' Header: <kmfun@sbcglobal.net>
Subject: The decision to suspend your account. Waiting for payment.
Timestamp: 11:30:10 CDT, Wednesday 26 June 2019
Message-ID: <D3E398DB6FA8A02C1C672490575FD3E3@12I28OK6SM>


Client IP Address: 156.221.54.241
Client GeoIP Lookup: Egypt
Email Size: 2.5 kB
Encrypted? No

Tuesday, June 25, 2019

GET BACK TO ME

NOTE: This one demands you 'GET BACK TO ME" right from the subject line. He has names, but will only share one with you.  LOL What about that email address?  batchelders?  What is this from?  Perhaps it's the elders sending our their batch of emails teaching the newbies how it's done?  Next generation of theives
in training?


From: "Comrade. Des van Rooyen" <chuck@batchelders.com> To: Recipients <chuck@batchelders.com>  16:50:46 CDT, Monday 24 June 2019


From: Comrade Des van Rooyen

Republic of South Africa

Please permit me to write to you irrespective of the fact we have not met before. My names are Comrade Des van Rooyen as indicated above; former Minister of
Cooperative Governance and Traditional Affairs and thereafter Minister of Finance of the Republic of South Africa.

I write this proposal which I believe would be of great interest to you and for your consideration, and I also apologize for intruding into your private
email address because I know that this e-mail will come to you as a surprise. But however strange or surprising this contact might seem to you as we have not
met personally or had any dealings in the past, to this infect, I humbly ask that you take due consideration of its importance and immense benefit it will be
to both of us. Please do not despair because I got your email address from a business advertising website on the Internet before making my contact with you.

I am in search of an Agent/Business person to assist me and my former principal, Former president of the republic, Comrade Jacob Zuma in transferring the sum
of $12,500,000 (Twelve Million, Five Hundred Thousand United States dollars) and subsequently invest it in Property / Real Estate Ventures. In case you wonder
the source of fund, during my time as the Finance Minister we over-invoiced a contract and deposited the proceed in a secured bank/ finance house in Real
Madrid, Spain with hope of using it after our retirement.

But due to the ongoing state capture which implicates me and my principal, we have decided to transfer this money out of where it is currently deposited
presenting you as the beneficiary to avoid the searchlight of the government of the day.

Presently, I am incapacitated to travel out of the country due to the fact that my travelling documents was seized by the investigating officers and the
government of the day but I will delegate my trusted partner upon receipt of your response to this mail so that you will communicate directly with him on the
way forward.

Subject to formal partnership agreement, we are prepared to share this fund with you on the following terms: 35% will be for you, 10% for transaction
expenses that will be made from both ends 55% will be for me and my principal. If you are interested in dealing with us on these terms, please let me know so
that I make you a formal offer to partner with us and forward to you the proposed strategy or plan of transfer of the fund.

Please include your direct mobile telephone number in your reply to this mail for easier communication.

Kind regards

Comrade Des van Rooyen




Message ID: <20190624215044.1.85A7386A602596FB@batchelders.com>
Return Path: <bounce+d0dd5e.f268db- @batchelders.com>
Reply To: comrade00rooyen@gmail.com
MIME Version: 1.0
Content Type: multipart/alternative; boundary="===============0644325175=="
Received:
from mx1-us2.ppe-hosted.com (unknown [10.7.65.176]) by pure.maildistiller.com with ESMTPS id 1B5334006A for < >; Mon, 24 Jun 2019 21:50:46 +0000 (UTC)

from so254-55.mailgun.net (so254-55.mailgun.net [198.61.254.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us2.ppe-hosted.com with ESMTPS id 79622680074 for < >; Mon, 24 Jun 2019 21:50:45 +0000 (UTC)

from outbound.service-hosting.net (pfsensejdc.service-hosting.net [66.85.72.51]) by mxa.mailgun.org with ESMTP id 5d1145b4.7f646ccda030-smtp-out-n01; Mon, 24 Jun 2019 21:50:44 -0000 (UTC)

from wmail.service-hosting.net (unknown [10.2.0.12]) by outbound.service-hosting.net (Postfix) with ESMTP id 8C9D8FFC43; Mon, 24 Jun 2019 17:50:41 -0400 (EDT)

from [23.92.216.199] (UnknownHost [23.92.216.199]) by w2k8.service-hosting.net with SMTP; Mon, 24 Jun 2019 17:50:34 -0400


Envelope Sender: <bounce+d0dd5e.f268db- @batchelders.com>
'From' Header: "Comrade. Des van Rooyen" <chuck@batchelders.com>
Subject: GET BACK TO ME
Timestamp: 16:50:46 CDT, Monday 24 June 2019
Message-ID: <20190624215044.1.85A7386A602596FB@batchelders.com>


Client IP Address: 198.61.254.55
Client GeoIP Lookup: United States
Email Size: 8.3 kB
Encrypted? No

GOOD DAY....93.46.02.201

From: "Mr. Flint John" <info@office.net> To: Recipients <info@office.net>  17:26:17 CDT, Monday 24 June 2019


Greeting's: My name is Flint John, a senior Auditing Officer with the reserve bank of South Africa, I write you this proposal in good faith and if you are not interested, please ignore this mail and go about your normal business, I have very vital information that will benefit our families to give to you, but first I must have your trust before I review it to you because it involved (GBP 15,000.000.00) Fifteen Million Briti9sh Pound Sterling and I will not want it exposed for any reason and I hope that you would not betray me. I will wait to hear from you ASAP, On my private email:flintjohn001@gmail.com Yours faithfully, Mr. Flint John


Message ID: <a53491671a56415d9f8bf387c9506d79@E13-01.ads.it>
Return Path: <bounces+SRS=mlBOW=UX=office.net=info@avvocaturastato.onmicrosoft.com>
Reply To: <flintjohn001@gmail.com>
MIME Version: 1.0
Content Type: text/plain; charset="iso-8859-1"
Received:
from mx1-us4.ppe-hosted.com (unknown [10.7.66.39]) by pure.maildistiller.com with ESMTPS id AAE0C4004D for < >; Mon, 24 Jun 2019 22:26:16 +0000 (UTC)

from EUR04-HE1-obe.outbound.protection.outlook.com (mail-he1eur04hn2057.outbound.protection.outlook.com [52.101.137.57]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by mx1-us4.ppe-hosted.com with ESMTPS id 2F41880063 for < >; Mon, 24 Jun 2019 22:26:16 +0000 (UTC)

from AM6PR0402CA0008.eurprd04.prod.outlook.com (2603:10a6:209::21) by DB8PR04MB5723.eurprd04.prod.outlook.com (2603:10a6:10:a9::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2008.16; Mon, 24 Jun 2019 22:26:05 +0000

from VE1EUR02FT063.eop-EUR02.prod.protection.outlook.com (2a01:111:f400:7e06::207) by AM6PR0402CA0008.outlook.office365.com (2603:10a6:209::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2008.16 via Frontend Transport; Mon, 24 Jun 2019 22:26:05 +0000

from postaweb.avvocaturastato.it (93.46.12.221) by VE1EUR02FT063.mail.protection.outlook.com (10.152.13.148) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.2008.13 via Frontend Transport; Mon, 24 Jun 2019 22:26:04 +0000

from E13-01.ads.it (10.148.5.242) by E13-01.ads.it (10.148.5.242) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Tue, 25 Jun 2019 00:20:22 +0200

from [37.49.230.24] (37.49.230.24) by E13-01.ads.it (10.148.5.242) with Microsoft SMTP Server id 15.0.1473.3 via Frontend Transport; Tue, 25 Jun 2019 00:20:21 +0200



Envelope Sender: <bounces+srs=mlbow=ux=office.net=info@avvocaturastato.onmicrosoft.com>
'From' Header: "Mr. Flint John" <info@office.net>
Subject: GOOD DAY....93.46.02.201
Timestamp: 17:26:17 CDT, Monday 24 June 2019
Message-ID: <a53491671a56415d9f8bf387c9506d79@E13-01.ads.it>


Client IP Address: 52.101.137.57
Client GeoIP Lookup: United States
Email Size: 6.3 kB
Encrypted? No

Monday, June 24, 2019

Urgent Reply

NOTE:  Intelligence monitoring?   LOL ... more like monitoring for idiots that fall for this million dollar load of crap.


From: opcw32@yahoo.com To:  11:18:36 CDT, Monday 24 June 2019


Attention Beneficiary, Through our intelligence monitoring unit we discovered your email listed as BENEFICIARY. The United Nations Organization have agreed to compensate you with the sum of (US$2,500,000.00) (Two Million Five Hundred thousand US Dollars) This includes all foreign contractors that may have not received their contract and sum people that have had an unfinished transaction. This is to inform you that your (US$2,500,000.00) USD will be send to you via ATM VISA CARD. The total amount mentioned above is with ATM Office. Here is what he may require from you. full Name.... Country.......... Address....... Tel........ ID card.......... Contact him immediately for your compensation payment of (US$2,500,000.00) he will send it to you immediately. We have concluded our effect to your payment through ATM VISA CARD. Contact our office in Benin with bellow information. Director; Dr. Daniel Wasso E-mail; cardservicesdept@citromail.hu Tel: +229 6905 6711 Kind Regards Helen Hadia


Message ID: <1340147240.1151994.1561393111427@mail.yahoo.com>
Return Path: <opcw32@yahoo.com>
Reply To: cardservicesdept@citromail.hu
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Received:
from mx1-us1.ppe-hosted.com (unknown [10.110.48.234]) by pure.maildistiller.com with ESMTPS id 2A0488006C for <    >; Mon, 24 Jun 2019 16:18:36 +0000 (UTC)

from sonic304-9.consmr.mail.bf2.yahoo.com (sonic304-9.consmr.mail.bf2.yahoo.com [74.6.128.32]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us1.ppe-hosted.com with ESMTPS id 0B3BF7800E9 for <   >; Mon, 24 Jun 2019 16:18:35 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic304.consmr.mail.bf2.yahoo.com with HTTP; Mon, 24 Jun 2019 16:18:34 +0000



Envelope Sender: <opcw32@yahoo.com>
'From' Header: opcw32@yahoo.com
Subject: Urgent Reply
Timestamp: 11:18:36 CDT, Monday 24 June 2019
Message-ID: <1340147240.1151994.1561393111427@mail.yahoo.com>


Client IP Address: 74.6.128.32
Client GeoIP Lookup: United States
Email Size: 3.9 kB
Encrypted? No

United Nations Inspection Agency

NOTE:  I really, truly hope that NO ONE believes this airplane load of crap!!!


From: "Mr. David" <mis@mydomain.com> To: Recipients <mis@mydomain.com>  21:48:21 CDT, Sunday 23 June 2019


Hartsfield–Jackson Atlanta International Airport Address:6000 N Terminal Pkwy, Atlanta, GA 30320, USA. I am Mr.David Wilson , Head Officer-in-Charge, Administrative Service Inspection Unit United Nations Inspection Agency in Hartsfield-Jackson International Airport Atlanta, Georgia. During our investigation, I discovered an abandoned shipment through a Diplomat from United Kingdom which was transferred from JF Kennedy Airport to our facility here in Atlanta, and when scanned it revealed an undisclosed sum of money in 2 Metal Trunk Boxes weighing approximately 110kg each. The consignment was abandoned because the Content was not properly declared by the consignee as money rather it was declared as personal effect/classified document to either avoid diversion by the Shipping Agent or confiscation by the relevant authorities. The diplomat's inability to pay for Non Inspection fees among other things are the reason why the consignment is delayed and abandoned. By my assessment, each of the boxes contains about $4M or more. They are still left in the airport storage facility till today. The Consignments like I said are two metal trunk boxes weighing about 65kg each (Internal dimension: W61 x H156 x D73 (cm) effective capacity: 680 L) Approximately. The details of the consignment including your name and email on the official document from United Nations' office in London where the shipment was tagged as personal effects/classified document is still available with us. As it stands now, you have to reconfirm your, (1) Full Name: (2) Phone Number: (3) full address: (4) Occupation: (5) Sex: so I can cross-check and see if it corresponds with the one on the official documents. It is now left to you to decide if you still need the consignment or allow us repatriate it back to UK (place of origin) as we were instructed.(REPLY TO THIS EMAIL : (davidwilson.agent@gmail.com) As I did say again, the shipper abandoned it and ran away most importantly because he gave a false declaration, he could not pay for the yellow tag, he could not secure a valid non inspection document(s), etc. I am ready to assist you in any way I can for you to get back this packages provided you will also give me something out of it (financial gratification). You can either come in person, or you engage the services of a secure shipping/delivery Company/agent that will provide the necessary security that is required to deliver the package to your doorstep or the destination of your choice. I need all the guarantee that I can get from you before I can get involved in this project. Please Reply this email strictly at ( davidwilson.agent@gmail.com ) Best Regards, Mr David Wilson Head Officer-in-Charge Administrative Service Inspection Unit E-mail: ( davidwilson.agent@gmail.com ) CELL PHONE: +1 9162340077


Envelope Sender: <mis@mydomain.com>
'From' Header: "Mr. David" <mis@mydomain.com>
Subject: United Nations Inspection Agency
Timestamp: 21:48:21 CDT, Sunday 23 June 2019
Message-ID: <201906240247.x5O2dqCB038251@server13.sojung.net>


Client IP Address: 58.229.253.139
Client GeoIP Lookup: Korea, Republic of
Email Size: 7.5 kB
Encrypted? No

Friday, June 21, 2019

Perenco Oil and Gas 19/06/2019

So wrong, on so many levels!


From: "Mrs. Carrie Perrodo"<sales@cidadeonline.com.br> To: 15:55:29 CDT, Friday 21 June 2019


Message ID: <0edc99$1ie600@mail2.kharafinational.com>
Return Path: <prvs=068b9e51a=sales@cidadeonline.com.br>
Reply To: <mrscarrieperrodo9877@gmail.com>
MIME Version: 1.0
Content Type: text/plain; charset="Windows-1251"
Received:
from mx1-us5.ppe-hosted.com (unknown [10.7.65.198]) by pure.maildistiller.com with ESMTPS id 7C37D2C0058 for < >; Fri, 21 Jun 2019 20:55:28 +0000 (UTC)

from mail2.kharafinational.com (mail2.kharafinational.com [168.187.226.74]) by mx1-us5.ppe-hosted.com with ESMTP id E54BA8005F for < >; Fri, 21 Jun 2019 20:55:27 +0000 (UTC)

from unknown (HELO User) ([41.203.78.218]) by mail2.kharafinational.com with ESMTP; 21 Jun 2019 23:55:15 +0300


I am Mrs. Carrie Perrodo, Co-Founder of Perenco, an Oil and gas exploration and production, natural gas and LNG trading and transportation, oil refining. I will appreciate if you will allow me to trust you as my humanitarian project manager, The sum of (US$6.8Million Dollars). Kindly come back to me in reply via my project verified e-mail address if accepted by you. E-mail: mrscarrieperrodo7642134@gmail.com You can check on my bio-data page to get a proper understanding of me. https://en.wikipedia.org/wiki/Carrie_Perrodo Remain Blessed! Mrs. Carrie Perrodo Perenco Oil and Gas Humanitarian Project



Envelope Sender: <prvs=068b9e51a=sales@cidadeonline.com.br>
'From' Header: "Mrs. Carrie Perrodo"<sales@cidadeonline.com.br>
Subject: Perenco Oil and Gas 19/06/2019
Timestamp: 15:55:29 CDT, Friday 21 June 2019
Message-ID: <0edc99$1ie600@mail2.kharafinational.com>


Client IP Address: 168.187.226.74
Client GeoIP Lookup: Kuwait
Email Size: 2.9 kB
Encrypted? No

I AWAIT YOUR IMMEDIATE RESPONSE

From: Mark Anthony Blackstone <sakiratubello9@gmail.com> To: undisclosed-recipients:; 15:46:05 CDT, Thursday 20 June 2019


Message ID: <CAGBP_KmzLiRx_rS+bps5oCMTEQqFMweLre==eLE6tJV3FdHp9A@mail.gmail.com>
Return Path: <sakiratubello9@gmail.com>
Reply To: markblackst24@gmail.com
MIME Version: 1.0
Content Type: multipart/alternative; boundary="0000000000002dffa5058bc76f2a"
Received:
from mx1-us2.ppe-hosted.com (unknown [10.7.65.176]) by pure.maildistiller.com with ESMTPS id 78361140053 for <   >; Thu, 20 Jun 2019 20:46:05 +0000 (UTC)

from mail-wm1-f66.google.com (mail-wm1-f66.google.com [209.85.128.66]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us2.ppe-hosted.com with ESMTPS id E878B68008C for < >; Thu, 20 Jun 2019 20:46:04 +0000 (UTC)

by mail-wm1-f66.google.com with SMTP id s3so4342942wms.2 for < >; Thu, 20 Jun 2019 13:46:04 -0700 (PDT)


FOR YOUR ATTENTION

CLIENT TRANSACTION REF: DV557-22S
I am reaching out to you in a matter of urgency, time is of the essence. One of my deceased client, who happens to share the same last name as yourself died intestacy. I need you to stand as the administrator or executor of her estate. I will explain all the necessary strategy and steps in full details and I am willing to supply you with full verifiable. Please note I do not intend to waste your time and I will appreciate if you do the same and notify me if we have a deal!

I honestly appreciate your attentiveness on this matter!

Kind regards
Mark Anthony Blackstone



Envelope Sender: <sakiratubello9@gmail.com>
'From' Header: Mark Anthony Blackstone <sakiratubello9@gmail.com>
Subject: I AWAIT YOUR IMMEDIATE RESPONSE
Timestamp: 15:46:05 CDT, Thursday 20 June 2019
Message-ID: <CAGBP_KmzLiRx_rS+bps5oCMTEQqFMweLre==eLE6tJV3FdHp9A@mail.gmail.com>


Client IP Address: 209.85.128.66
Client GeoIP Lookup: United States
Email Size: 4.3 kB
Encrypted? No

CONGRATULATIONS! YOU HAVE AWARDED PRIZE OF $2,000,000.00

NOTE: The stupidity of this speaks for itself


From: visa card <visacard516@gmail.com> To: martin_clayton@att.net, spongeratc@aol.com, Rem@pbcwhof.net, mayabbs@hotmail.com, tmcmachine@aol.com, mike.mccormick@caring4kids.com, harry.mcdonald@dla.mil, mcdonaldwrestlers@prodigy.net, mcfalladventures@charter.net, mcgin@verizon.net, dennis_mcgrane@sbcglobal.net, rickmckinney@cusd.com, mmclarney@gmail.com, bmeckley@hotmail.com, meierEce@gmail.com, mekeel.ryan@gmail.com, donmekeel@hotmail.com, cartmn3223@aol.com, broncosman5608@gmail.com, stingrae1@rcn.com, jkmiddle@juno.com, miesseam@yahoo.com, mmiller@psd202.org, mmillward@verizon.net, mwwoa60@gmail.com, rasseler2@yahoo.com, moon@utlx.com, rainyday103@hotmail.com, ThomasJ.Moore723@gmail.com    01:15:12 CDT, Friday 21 June 2019


Message ID: <CAOfUfenkV2LQF6jtWwxqvXuk_WCFvUrQixEz=A_Xexq1-ADAqA@mail.gmail.com>
Return Path: <visacard516@gmail.com>
Reply To: visacard89@yahoo.com
MIME Version: 1.0
Content Type: multipart/alternative; boundary="0000000000008db6ed058bcf6211"
Received:
from mx1-us2.ppe-hosted.com (unknown [10.110.49.74]) by pure.maildistiller.com with ESMTPS id 1295D8006A for < >; Fri, 21 Jun 2019 06:15:12 +0000 (UTC)

from mail-oi1-f196.google.com (mail-oi1-f196.google.com [209.85.167.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us2.ppe-hosted.com with ESMTPS id F220080063 for <  >; Fri, 21 Jun 2019 06:15:11 +0000 (UTC)

by mail-oi1-f196.google.com with SMTP id e189so3871714oib.11 for <  >; Thu, 20 Jun 2019 23:15:11 -0700 (PDT)


Visa USA Inc.
2000 Purchase Street
Purchase, NY 10577
USA.

Dear Lucky Winner!

Congratulations, we humbly wish to inform you that you have awarded prize
of two million US dollars ($2,000,000.00) for the yearly lottery promotion
which was organized and sponsored by Visa USA Inc. and Microsoft
International for the introduction of the new visa credit cards gold covers.

The Visa USA Incorporated and Microsoft! team arrange and gather all the
e-mail addresses of people that are active on-line, among the billion that
subscribed to all email addresses and others, we only select Nine (9)
candidates per annually as our winners through Electronic Balloting System
(EBS) without the candidate been applying. This visa USA Inc. - credit
cards lottery was aimed to help families and communities with the current
global crisis and also aimed to help reduce poverty in the global world.

This visa USA lottery prize must be claimed not later than fifteen (15)
working days from date of draw notification after the draw date in which
prize has won. Stay Connected, any prize not claimed within this period (15
days) will be forfeited.

Contact Person: -------- Mr. Donald Thompson (Administrator)
E-mail Address: --------- www.visacard89@yahoo.com
Toll-Free Number: ---------------- +233544930130

Kindly fill the below form and contact your claims administrator via e-mail
/phone for the 48hours delivery of your winners certificate and your
Co-Branded visa credit cards gold cover of two million US dollars
($2,000,000.00). Find out more, you are therefore advised to send the
following information to the above email address to facilitate and process
your winning prize payment with the appointed paying bank.

Ticket No #: 51345810
Lucky winner's No#: +233544930130
Reference code No#: D7627270008VCL
Registration codes No#: 5148/4178-2019VCL

Please follow our guidelines outlined at the body of this message.
Send your Identification numbers/your personal information immediately to processing office.

Full Names: ___________________________________________
Contact Address: ______________________________________
Cell Phone: ___________________________________________
Country of Residence: __________________________________

Quote your complete names, winning amount and your direct cell/home phone number so that they can honor your request. All winners shall be paid in accordance with his/her settlement center, now take the next step and claim your prize and say thanks to Visa USA Incorporated. Contact your claims administrator at: www.visacard89@yahoo.com

Make Yourself at Home. Make the Visa Inc. - credit cards your go, power to you.
© 1994 - 2019 Visa USA Incorporated - Credit Cards. All rights reserved.



Envelope Sender: <visacard516@gmail.com>
'From' Header: visa card <visacard516@gmail.com>
Subject: CONGRATULATIONS! YOU HAVE AWARDED PRIZE OF $2,000,000.00
Timestamp: 01:15:12 CDT, Friday 21 June 2019
Message-ID: <CAOfUfenkV2LQF6jtWwxqvXuk_WCFvUrQixEz=A_Xexq1-ADAqA@mail.gmail.com>


Client IP Address: 209.85.167.196
Client GeoIP Lookup: United States
Email Size: 9.7 kB
Encrypted? No

My Dear Friend:

From: pwrwq56666@yahoo.com To:  05:16:34 CDT, Friday 21 June 2019



My Dear Friend: I have been waiting for you since to hear from you about your fund of ($30.800.000,00 Million usd) but i didn’t heard from you I’m here to inform you that I later find out that your fund has been delivered by courier company due to the amount is large and is very big risk to deliver that such amount through courier company since it doesn't have necessary certificate and i trying since to contact you via your phone which i fail many times. Your country airport Custom will demand for Clearance Certificate and many other certificate as system of delivering in your country, I check the file of your bank draft and it will be very difficult to deliver it without backing it up with the necessary certificate, And i will not like any condition by which your fund will be on hold by any custom or any security as you know the amount in the bank draft. I make an solid arrangement with Director of BANK OF AFRICAN BENIN REPUBLIC FOR WIRE TRANSFER OF THIS FUND INTO YOUR ACCOUNT.Now your fund was deposited in AFRICAN BANK BENIN REPUBLIC for wire transfer, Its my pleasure to inform you that i have verify from the bank director regarding the transfer of your fund and it was good news because the requested fee was less expensive for you to afford. your consignment containing your fund ($30,800.000,00 Million usd) i have deposited it with the UBA BANK OF AFRICAN BENIN. so that your fund will be wired to your account immediately you contact the bank director with your banking details. However i went to UBA BANK OF AFRICAN BENIN. to discuss this with the bank director as its has not been delivered to you However he told me that your fund can be transferred to you via a direct wire transfer(KTT) into your account.He told me to instruct you to contact the bank to apply for a direct wire transfer into your account to avoid loosing your fund due to delay.Therefore you can contact the bank with the below information, send to them your banking information. 1.YOUR FULL NAME:============== 2.YOUR BANK DETAILS============ 3.YOUR PHONE:================== 4.YOUR AGE:==================== 5.YOUR SEX:==================== 5.YOUR COUNTRY:================ 6.YOUR OCCUPATION:============= ATTACH COPY OF YOUR ID:======== EMAIL ADDRESS:======== EMAIL PASSWORD:======== YOUR NEXT OF KIN NAME :======== FAMILY: PHONE AND ADDRESS:======== Send an email to the bank with the above bank email and apply for your wire transfer as i have informed the bank manager about you already.On receipt of your fund into your account endeavor to inform me immediately you receive your fund in your account. Thanks mail:ubabank1918@gmail.com mail:ubabank190@aol.com



Envelope Sender: <pwrwq56666@yahoo.com>
'From' Header: pwrwq56666@yahoo.com
Subject: My Dear Friend:
Timestamp: 05:16:34 CDT, Friday 21 June 2019
Message-ID: <1266217175.95598.1561112190880@mail.yahoo.com>



Client IP Address: 74.6.131.123
Client GeoIP Lookup: United States
Email Size: 6.0 kB
Encrypted? No

Thursday, June 20, 2019

Compliments of the season to you and members of your family.

NOTE: A Scammer, letting you know you are a victim of a scam .... of course, by replying to this you most certainly, 100%, be a scam victim.  How ironic.  We all know Germany is NOT in Nigeria .... right?


From: "From Michael Green"<pastywgiginr@solomonbaron.com> To:  18:34:37 CDT, Wednesday 19 June 2019


Compliments of the season to you and members of your family. Dear ATTENTION: BENEFICIARY. It is my pleasure to officially inform you that your name was on the list of those scammed victims, who was compensated by the Nigerian Federal Government to the sum of $475,000 (US dollars). Already the sum of $75,000 (seventy five thousand US dollars) has been issued an ATM at Zenith Bank headquarters, Plot 84, Ajose Adeogun Street, Victoria Island Lagos, Nigeria, awaiting the confirmation of your; 1)Full names 2)Address 3)telephone number, and 4)e-mail subject to the confirmation of your embassy. You are directed to contact the account officer in charge of foreign remittance, Chidi Martins; via email;(compliment.sseason81@yahoo.com) Kind regards, FOR: Public Affairs Section, Abuja Embassy of the United States of America Plot 1075 Diplomatic Drive Central District Area, Abuja, Nigeria. Best regards, From Michael Green compliment.sseason81@yahoo.com



Envelope Sender: <pastywgiginr@solomonbaron.com>
'From' Header: "From Michael Green"<pastywgiginr@solomonbaron.com>
Subject: Compliments of the season to you and members of your family.
Timestamp: 18:34:37 CDT, Wednesday 19 June 2019
Message-ID: <C34748D156AF485AA7D649B293F96C60.MAI@ex-ro.de>



Client IP Address: 85.25.213.126
Client GeoIP Lookup: Germany
Email Size: 2.2 kB
Encrypted? No

Monday, June 17, 2019

PAYMENT NOTIFICATION

NOTE: We go from Nigeria to Texas to Tunisia in this scam. Nevermind the poor English and the fact the writer is telling YOU, the reader, that you're terminally ill! Yet somehow, in your powers of mortality, you might be able to stick around a month after your dead.   LOL  Why would anyone take this seriously?



From: "Mrs Robin Sanders"<zzuniga@bcm.tmc.edu> To:    20:20:12 CDT, Sunday 16 June 2019




Attn; Beneficiary,

I am Mrs Robin Sanders, Former U.S.A Ambassador to Nigeria. With reference to your entitlement fund and inline with the CHANGE OF BENEFICARY'S APPLICATION, signed by Mrs. Glenda F. Ward with your purported authorization. This issue has been carefully examined and we have declined Mrs. Ward's application as the application lacks regular signature. But Did you ever instruct Mrs Glenda F. Ward to claim your fund worth US$7.000.000? Below is the bank account information provided by Mrs Glenda F. Ward saying that you authorized her to claim your fund that you are terminally ill.

Bank of America
Benf: N Micheal Igboalisi
ACCT: 586025513245
Routing: 111000025
Bank Address 9711 Bissonnet St. Houston, Tx 77036

If you had not authorized the change of your bank account in respect to your outstanding entitlement Payment, therefore notify me immediately as the notification / declaration was supported with a sworn affidavit from Lagos high court ref: ilk /jj/202/k2015, dated 10th June 2019 and signed by Mrs. Glenda Ward who claim and stated in the sworn declaration that you authorized her to claim the said fund on your behalf to a different bank account in the U.S.A as stated above because you were terminally ill and the Doctor who is incharge of your case stated that you will not stay more than one Month before passing away.

This development has caused lots of discrepancies in your payment file that is why we had to suspend your payment and prompted to contact you directly before re-validating your payment. You can be rest assured that I will do everything within my capacity to successfully actualize the quick transfer of your fund to any of your nominated bank account.

Kindly get back to me as soon as possible so that I will direct you on what to do.

Sincerely Yours
Mrs Robin Sanders
Fmr. U.S Ambassador





Envelope Sender: <zzuniga@bcm.tmc.edu>
'From' Header: "Mrs Robin Sanders"<zzuniga@bcm.tmc.edu>
Subject: PAYMENT NOTIFICATION
Timestamp: 20:20:12 CDT, Sunday 16 June 2019
Message-ID:


Client IP Address: 41.226.22.114
Client GeoIP Lookup: Tunisia
Email Size: 3.9 kB
Encrypted? No

Sunday, June 16, 2019

CONGRATULATIONS FROM FACEBOOK!!!!!

NOTE:  Really?!?!?!?  Just ... really?????



From: "Facebook Lottery Department."<info@facebook.org> To:     20:04:42 CDT, Friday 14 June 2019


CONGRATULATIONS FROM FACEBOOK!!!!!

Facebook is one of the largest Social Networking site which valued more than $100 Billion Dollars and also expecting its Ten Billion Users to come mainly from Mobile devices than desktop Users by this year 2019, Facebook founder Mark Zuckerberg has decided to boost Users and Companies a WINDOW OF OPPORTUNITY by Lottery Program and Initial Public Offer said in a press release.

We are oblige to congratulate and notify you that your Face-Book profile that was used by you to register an Account with Facebook has emerged you as one of the Luck Winners in Category "A" which subsequently won you sum of (one million United State Dollars($1,000.000.00).) Your fund has been insured and its ready for the immediate release to you without hitches.

Details of your Winning are:
Winning Number:- FB392-US7720
Batch Number:- 0024892JT
Serial Number:- DT119027834SZ
Ticket Number:- 47061725

The promo was done to serve as a means of appreciation to visitors on our site and also to help people to fight off poverty and to maintain the standard of living.

Meanwhile, a man sent a letter to our office few days ago, claiming to be your true representative. Here are his provided information.

Bank Name: BB&T Bank, USA.
1801 ADAMS MILL ROAD
WASHINGTON,DC 20009-1901
Account Number:1090000009620
Routing Number:054001547
Account Name : Gregory Phillips>

Please, do reconfirm to this office, as a matter of urgency if this man is from you. Note however that, you are not to send money to anyone to receive you funds as the authority is against that, and don't let people, impersonator fool you or scam you, otherwise you will regret it after wasting money and effort.

However for the purpose of proper verification among other relevant information, it is imperative that you forward your claims to ourn claim department with the below details.
FULL NAME:
FULL CONTACT ADDRESS:
MOBILE PHONE NUMBER:
OCCUPATION:
MARITAL STATUS AND AGE:
NATIONALITY / COUNTRY:
YOUR EMAIL ADDRESS:

Correspondences. Furthermore, if there is any change in email address please contact us on time.
If you are not interested please do not bother to reply and CONGRATULATIONS ONCE AGAIN FROM

FACEBOOK!
Thanks,


Mr.Mark Zuckerberg .
FACEBOOK 2019
(650) 665-9113
Email:facebookdep444@gmail.com



Envelope Sender: <info@facebook.org>
'From' Header: "Facebook Lottery Department."<info@facebook.org>
Subject: CONGRATULATIONS FROM FACEBOOK!!!!!
Timestamp: 20:04:42 CDT, Friday 14 June 2019
Message-ID: <F0BEBDC658ED4D6EA0873FC667C796AF.MAI@host.oasiscloud.com>



Client IP Address: 67.225.146.249
Client GeoIP Lookup: United States
Email Size: 6.6 kB
Encrypted? No